Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 336

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Tips for Parenting at a dual language school (non native)
Kids Online Safety Act social media safety bill advances in Senate
Private companies added just 44,000 workers in July, below expectations, ADP reports
Situational Awareness hedge fund meltdown was a warning shot for leveraged markets, BofA CEO says
Oil prices fall on negotiations to manage ship traffic in Strait of Hormuz
Movie: The Egg and I
Tanger CEO says World Cup drove up traffic, sales this summer
S&P 500 gives up gain as 4-day rally loses momentum; Dow boosted by Nvidia: Live updates
Disney tops earnings estimates as parks and streaming offer a boost
Tales from the Crypt: The Man Who Was Death